We have third party vendors who needs to access a legacy device(IP address 172.16.10.6) which will accept connections to it only on a particular IP(eg.172.16.10.5). Before migrating to Checkpoint Appliance, we were able to assign each remote access vendor a Remote Address on the "SSTP VPN profile" that we created on the appliance.
Third Party Vendor --->(connecting with SSTP client settings on Windows Laptop)-->Gets assigned Remote IP address from SSTP config on Router---> gets VPN established on the Router---> Third Party vendor is now able to access the Legacy device. The Legacy Device (IP address 172.16.10.6) is on a VLAN (172.16.10.x/24) that has other devices in that VLAN.
On Checkpoint, we have assigned another subnet (10.100.200.x) that is not used in our internal LAN to be used for leasing addresses to Remote Access Users(Third Party Vendors).
Would we able to
- assign static IP address to Remote Users connecting to Remote Access VPN configured on Checkpoint 1570 appliance(eg. 10.100.200.5)?
- Get this static IP address to be NATed to the existing Internal LAN subnet address, so that the legacy device can accept this connection. (eg. 10.100.200.5 <Natted to>172.16.10.5, so that the legacy device with IP 172.16.10.6 will think that the Remote access VPN is 172.16.10.5 and provide access)
Hope this makes sense.